exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Joomla Health / Fitness Stats Cross Site Scripting

Joomla Health / Fitness Stats Cross Site Scripting
Posted Jul 13, 2010
Authored by Sid3 effects

The Joomla Health and Fitness Stats component suffers from a cross site scripting vulnerability.

tags | exploit, xss
SHA-256 | 7e16eb893775a840fa688f416f50ee5b500c460082cb0902b1fee8fedb3a6357

Joomla Health / Fitness Stats Cross Site Scripting

Change Mirror Download
Name : Joomla Health & Fitness Stats Persistent XSS Vulnerability
Date : july 12,2010
Critical Level : HIGH
vendor URL :http://joomla-extensions.instantiate.co.uk/jcomponents/healthstats
Author : Sid3^effects aKa HaRi
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,Sonic,gunslinger_
greetz to :www.topsecure.net ,All ICW members and my friends :) luv y0 guyz
#######################################################################################################
Description
To allow users of an Exercise & Fitness community site to be able to record their progress of various health and fitness measures such as body weight, blood pressure, number of press-ups in 60seconds, time for 1000m run etc. Goals can be set by the user which appear as red lines across the graph area. The user is also given the option to create 'custom stats' for which they can set the unit of measurement and whether best is highest or lowest.

This component also includes a Central Stats page which pulls together the most recent values of each user for each parameter and averages these for Male and Female users.
#######################################################################################################
Xploit: Persistent XSS Vulnerability

This vulnerability exists in the comments section.

1. Goto any of the option like HEALTH STATS,FITNESS STATS or CUSTOM STATS

2. Select Add/Update option and insert your xss script :)

3. Once inserted goto Edit records and check your xss :P

Attack Pattern:">><marquee><h1>XSS3d by Sid3^effects</h1><marquee>

DEMO URL : http://<site>/jcomponents/healthstats/statistics-demo

Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    53 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    0 Files
  • 15
    May 15th
    0 Files
  • 16
    May 16th
    0 Files
  • 17
    May 17th
    0 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    0 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close